KamoCRM

The *** cookie on login.* is HttpOnly, and no log line carries half a session id

Fixkamo-login
Name
lúc 00:11 24 tháng 9, 2026 UTC
Tác giả
Kamo
Cam kết
0eb2550

/api/login, /api/login/mfa and /api/session/select planted *** with httpOnly:false ("client- accessible for session checks") — but no browser code on login.* or kamo-internal reads it any more; kamo-internal carries the session per tab. A readable session cookie is one XSS away from a stolen session, so it is HttpOnly now. It also makes logout work as intended: the logout page deletes every cookie from script BEFORE calling /api/logout, so /api/logout never found *** to invalidate the session server-side; script can no longer delete it. Four log lines printed the first 32 hex characters of a session id (or of a login OTK) — they print lengths now.

Mọi thay đổi

Như những gì anh thấy vận chuyển?

Tất cả những thứ đó đều đến trong không gian làm việc của anh. Bắt đầu với kế hoạch miễn phí và đọc lại trang này trong một tháng.

Bắt đầu tự do mãi mãiXem truy cập